M&A due diligence · Clinical care providers
M&A Privacy & Security Due Diligence for Medical & Diagnostic Labs
Lab consolidation carries privacy risk most acquirers underprice: a legacy LIS archive with no clear retention discipline, consent and OLIS histories that don't transfer cleanly, and a licence whose quality-management conditions may not survive a change of ownership intact. We diligence the specific liabilities a lab acquisition carries before the deal closes, not after the surprises show up in a hospital contract review.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
What due diligence has to examine in a lab acquisition
A lab's data and licensing footprint don't transfer as cleanly as a typical business's customer list, and diligence needs to look in the right places.
Legacy LIS archives and prior systems
Labs that have been through prior mergers or system migrations often carry results and requisitions in older systems nobody actively maintains, and those archives carry the same PHIPA obligations as anything in the current LIS.
Consent and OLIS contribution histories
A target lab's record of OLIS contributions and any patient consent-withdrawal requests needs review to confirm those histories are complete and can be honoured correctly after a systems migration.
LSCLA licence status and conditions
The operating licence under the Laboratory and Specimen Collection Centre Licensing Act, and whether its quality-management-program conditions have been consistently met, is a direct diligence item with regulatory consequences if gaps exist.
Custodian and agent relationships with hospitals
Every hospital and health-authority contract the target holds needs its custodian-or-agent position reviewed, since an unclear position becomes the acquirer's problem the moment the deal closes.
Prior incidents and regulator interactions
Any breach history, IPC correspondence or unresolved complaint against the target lab needs to surface during diligence, since liability for undisclosed incidents can follow the acquiring entity.
Reference-lab and vendor relationships
Existing send-out arrangements, LIS vendor contracts and instrument-service agreements each carry their own data-handling terms that need review before they're assumed as part of the deal.
Regulatory map
The regulatory continuity questions a lab deal has to answer
Privacy and licensing obligations don't reset at closing; they transfer with the entity, and diligence has to confirm what's actually being inherited.
LSCLA licence transferability
A change of ownership can affect what's required to keep an LSCLA licence active, and confirming this before close avoids a post-acquisition gap in a lab's legal ability to operate.
PHIPA custodian obligations surviving the transaction
Custodian status and the records it governs carry forward through an acquisition, meaning the acquiring entity inherits accountability for legacy data whether or not it was disclosed during diligence.
Quebec health-information Act continuity
A target lab serving Quebec patients carries obligations under the province's health-information Act, including its incident register and designated-person requirements, that need to be assessed for continuity post-close.
PIPEDA accountability for acquired data
PIPEDA's accountability principle means the acquiring organization becomes responsible for personal information it now holds, including legacy archives it may not have fully assessed before signing.
What goes wrong
What undisclosed lab liabilities look like
The risks here tend to surface in integration, months after close, unless diligence finds them first.
An unassessed legacy archive with no retention discipline
A prior system nobody actively governs can hold years of requisitions and results well past any legitimate retention period, creating exposure the acquiring lab now owns without ever having created it.
A custodian-agent position that was never formalized
The same ambiguity the IPC addressed in its LifeLabs order can exist quietly in a target's hospital contracts, and it becomes the acquirer's liability the moment the deal closes.
An undisclosed prior incident
A breach or complaint the target didn't fully disclose, or resolved informally without proper regulatory notification, can resurface as the acquiring entity's problem once the affected patients or a regulator learn of the change in ownership.
Licensing gaps discovered post-close
Quality-management-program conditions that weren't being met consistently at the target lab become a licensing risk the acquirer now carries, potentially affecting the ability to keep operating collection centres.
Our m&a due diligence for medical & diagnostic labs
What our due diligence covers in a lab transaction
We assess the target's actual privacy and licensing exposure so it can inform price, deal structure and integration planning, not surface after close.

Risk assessment of data handling and archives
Review of the target's current and legacy systems, including how requisitions, results and specimen metadata are retained and governed.
Compliance review against PHIPA and licensing conditions
Evaluation of the target's alignment with custodian obligations and LSCLA quality-management conditions, surfacing gaps before they become the acquirer's problem.
Custodian-agent and contract review
Examination of the target's hospital and health-authority contracts to confirm each relationship's privacy status is documented and defensible.
Incident and complaint history review
Assessment of prior breaches, regulator correspondence and unresolved complaints that could carry liability into the new ownership.
Integration planning support
Guidance on merging privacy practices, aligning policies and closing gaps identified during diligence so operations continue without a compliance interruption post-close.
How the engagement runs
How diligence runs on a lab acquisition timeline
We work within the deal's confidentiality and timeline constraints, prioritizing what most affects valuation and integration risk.
Step 1
Scope the review to the deal timeline
Confirm what data room access is available and prioritize the systems, contracts and licences most material to the transaction.
Step 2
Assess data, licensing and contract risk
Review legacy archives, LSCLA licence status, and hospital custodian-agent positions against PHIPA and provincial obligations.
Step 3
Report findings for negotiation
Deliver findings in a form that supports price adjustment, representation and warranty terms, or specific closing conditions.
Step 4
Support post-close integration
Help align the target's privacy practices and licensing status with the acquiring entity's program so gaps close quickly after the deal completes.
What it costs
What affects due diligence cost for a lab deal
Cost depends on the target's size, how many legacy systems and prior acquisitions are in its own history, how many hospital and health-authority contracts need review, and the deal timeline.
Diligence often runs on compressed schedules set by the transaction itself. Share the data room scope and closing timeline and we'll return a review plan sized to fit it.
Medical & Diagnostic Labs: M&A due diligence questions, answered
Custodian obligations for every record the target holds, including legacy archives, transfer with the entity regardless of what was disclosed during diligence. That means undisclosed breaches, incomplete consent-withdrawal handling, or an informal custodian-agent arrangement with a hospital client all become the acquirer's responsibility the moment the deal closes, which is why reviewing them before signing matters more than addressing them after.
We request access to prior systems still holding results or requisitions, assess what retention discipline, if any, has been applied, and review how consent-withdrawal requests, including OLIS-related ones, have been tracked and honoured historically. Where a target has been through a prior merger itself, this step often uncovers a second or third generation of legacy systems that were never fully consolidated or governed.
Not necessarily, and this needs confirmation well before close rather than assumed. Depending on deal structure, whether it's a share purchase or an asset purchase, licensing continuity under the Laboratory and Specimen Collection Centre Licensing Act can require notification or approval, and a gap here can affect the lab's ability to keep operating collection centres without interruption.
That ambiguity becomes a diligence finding worth pricing into the deal or resolving as a closing condition. The IPC's order against LifeLabs specifically required formalizing custodian-or-agent status with hospital clients, and an acquirer inheriting an unresolved version of that same question takes on the same regulatory exposure without having negotiated for it.
Far enough to cover the applicable statutory record-keeping periods and any prior ownership changes the target has been through, since incidents from a previous entity can still carry obligations forward. We also review whether past incidents were reported to the IPC or handled informally, since an informally resolved incident can still carry undisclosed liability.
Yes, and that's the point of running it before signing rather than after. Findings on legacy archive risk, licensing gaps or undisclosed incidents commonly inform purchase price, representations and warranties, or specific closing conditions requiring remediation, giving the acquirer leverage it wouldn't have once the transaction has already completed.
More for medical & diagnostic labs
Other services for this niche
About this service
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.